Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Trustindex is a Hungarian review aggregation widget developed by Trustindex Kft. It collects customer reviews from Google, Facebook, Trustpilot, Yelp and other sources and displays them as a JavaScript widget on retailer and SMB websites. The product is hosted in the European Union and is popular with WordPress, Shopify and Webflow sites.
Trustindex is a customer review aggregation widget developed by Trustindex Kft., a Hungarian company headquartered in Budapest. It pulls reviews from Google Business Profile, Facebook Pages, Trustpilot, Yelp, TripAdvisor and other connected sources, then displays them in carousels, badges and floating widgets on the customer website. It is widely used on WordPress, Shopify and Webflow sites in Europe.
Once the merchant connects their review sources to the Trustindex dashboard, the platform polls the third party APIs (Google, Facebook, Trustpilot) on a schedule, normalises the reviews, applies moderation filters, and serves the resulting feed to the JavaScript widget. The widget is loaded from cdn.trustindex.io, calls the Trustindex API on widget render and listens for view and click events.
The widget writes a small number of first party cookies (trustindex_session, trustindex_lang, trustindex_view) to remember the locale, the scroll position and to deduplicate impressions. It also captures visitor IP, user agent and the referring URL on the Trustindex side for anonymous impression statistics and fraud prevention. No advertising cookie is set.
Trustindex acts as a processor on behalf of the merchant for the display of reviews on its website. The widget cookies are non strictly necessary because the website would function without them, so Art 5(3) ePrivacy requires prior consent. Consent under Art 6(1)(a) GDPR is the correct legal basis. The Trustindex DPA should be added to the merchant records of processing.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The CMP should block the Trustindex script until the visitor accepts the relevant category (typically Statistics or Marketing). Use a static placeholder until consent is given. The privacy notice must mention Trustindex, the review sources connected and the location of processing (EU).
Trustindex hosts its production stack on Hetzner data centers in Germany and Hungary. Cloudflare provides the global CDN cache. The vendor states that personal data is processed and stored in the EU only. No transfer to the United States is performed in the standard configuration.
Add Trustindex to the cookie scan and the records of processing as a sub processor. Wrap the script through the CMP under Statistics or Marketing depending on the strictness of the local guidance. Display a static placeholder before consent. Verify the source review platforms also have a valid legal basis for the underlying review collection.
Websites using Trustindex must obtain user consent under GDPR regulations.
DPIA considerations
A full DPIA is generally not required for Trustindex when it is used to display aggregate reviews on a homepage or product page. A DPIA is recommended when the widget is combined with personalised recommendations, profiling of visitors based on review interaction, or when the site collects user generated reviews itself. Document Trustindex as a sub processor and verify the EU hosting clause in the contract.
Sample consent text
This site uses Trustindex, a Hungarian customer review aggregation service, to display Google, Facebook and Trustpilot reviews. With your consent, Trustindex loads its JavaScript widget and stores a small number of first party cookies to remember scroll position and record anonymous impressions. Your IP is processed for fraud prevention and aggregated statistics.
Third-party domains contacted
cdn.trustindex.ioapi.trustindex.iotrustindex.ioapp.trustindex.ioCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| trustindex_session | Strictly Necessary | Session | First party session cookie used to maintain widget state while the visitor browses the page. |
| trustindex_lang | Preferences | 12 months | First party preference cookie storing the locale chosen for the reviews widget. |
| trustindex_view | Statistics | 30 days | First party deduplication cookie used to count each visitor only once per widget view in anonymous impression statistics. |
Trustindex uses cookies for user preferences — inform visitors with a consent banner.
The Trustindex widget sets first party cookies trustindex_session (browser session), trustindex_lang (12 months, locale preference) and trustindex_view (30 days, impression deduplication). No advertising or cross site identifier is dropped. The Trustindex server also processes the visitor IP and user agent for anonymous statistics and fraud prevention.
Yes. The Trustindex widget loads third party content and writes non strictly necessary cookies for analytics, which means Art 5(3) ePrivacy applies and prior consent is required. Use a static placeholder to keep the page functional before consent is granted.
Consent under Art 6(1)(a) GDPR for the loading of the widget and its non essential cookies. The legitimate interest of the merchant (Art 6(1)(f)) covers the aggregation of public reviews on the Trustindex backend but not the dropping of analytics cookies on the visitor browser.
Not in the standard configuration. Trustindex hosts production data on Hetzner in Germany and Hungary. Cloudflare provides CDN caching globally but no personal data is persisted outside the EU. Verify the current sub processor list in your DPA, as Trustindex updates it occasionally.
A DPIA is generally not required for a simple display of aggregated reviews. It becomes relevant when the widget data is reused for personalised recommendations, when the merchant collects user generated reviews directly, or when the volume of impressions becomes very large.
Wrap the Trustindex script in your CMP under the Statistics or Marketing category. Block it until the visitor accepts. Use a static placeholder card with a Show reviews button. List Trustindex in the records of processing, sign the EU DPA and mention it in the privacy notice with the source platforms.
Comparable reviews aggregation widgets include Reviews.io, Yotpo, Loox, Stamped, Judge.me and Tagembed. Each has different data residency, pricing and sub processor terms. Review the DPA and sub processor list before switching.
List the three trustindex cookies (trustindex_session, trustindex_lang, trustindex_view) with their duration and purpose. Disclose the IP and user agent processing on the Trustindex side. Mention the source platforms (Google, Facebook, Trustpilot) so visitors understand the chain of recipients.